CVE-2021-29038: Medium severity liferay 7.4 ga vulnerability
In Liferay Impl before 5.18.4, Liferay Users Admin Web before 5.0.33, Liferay Login Web before 5.0.18, and Liferay Commerce Account Web before 3.0.7 from Liferay Portal (7.2.0 through 7.3.5), and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported versions does not obfuscate password reminder answers on the page, which allows attackers to use man-in-the-middle or shoulder surfing attacks to steal user's password reminder answers.
Other sources
Liferay Portal 7.2.0 through 7.3.5, and older unsupported versions, and Liferay DXP 7.3 before fix pack 1, 7.2 before fix pack 17, and older unsupported versions does not obfuscate password reminder answers on the page, which allows attackers to use man-in-the-middle or shoulder surfing attacks to steal user's password reminder answers.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-29038?
CVE-2021-29038 is categorized as a medium severity vulnerability, affecting password reminder answer visibility.
How do I fix CVE-2021-29038?
To fix CVE-2021-29038, update your Liferay Portal to version 7.3.6 or later and Liferay DXP to the appropriate fix packs.
What products are affected by CVE-2021-29038?
CVE-2021-29038 impacts Liferay Portal versions 7.2.0 to 7.3.5 and Liferay DXP versions prior to 7.3 fix pack 1 and 7.2 fix pack 17.
Can CVE-2021-29038 be exploited remotely?
Yes, CVE-2021-29038 can be exploited remotely through man-in-the-middle or shoulder surfing attacks.
What kind of attacks can take advantage of CVE-2021-29038?
CVE-2021-29038 can be exploited through attacks that expose unprotected password reminder answers to users.